FreeBSD 13

FreeBSD 13 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — subversion — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 6 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: Subversion — Multiple vulnerabilities in server code Related CVEs: CVE-2004-0397 CVE-2004-0749 CVE-2009-2411 CVE-2010-4539 CVE-2010-4644 CVE-2011-0715 CVE-2011-1752 CVE-2011-1783  +12 more Upstream summary: Subversion project reports: Subversion servers reveal 'copyfrom' paths that […]

Read more
How to Use Skaffold for Kubernetes Dev on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Use Skaffold for Kubernetes Dev on FreeBSD 13

Introduction This guide explains how to Use Skaffold for Kubernetes Dev on FreeBSD 13 on FreeBSD 13. FreeBSD uses the pkg(8) binary package manager, rc.conf(5) for service startup configuration, and pf(4) as its primary packet filter. There is no SELinux or AppArmor — instead, FreeBSD provides the MAC (Mandatory Access Control) framework and Capsicum for […]

Read more
FreeBSD 13 — lasso — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — lasso — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: lasso — signature checking failure Related CVEs: CVE-2021-28091 Upstream summary: entrouvert reports: When AuthnResponse messages are not signed (which is permitted by the specifiation), all assertion's signatures should be checked, […]

Read more
FreeBSD 13 — sge — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — sge — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 5 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: sge — local root exploit in bundled rsh executable Upstream summary: Sun Microsystems reports: The SGE 6.0u7_1 release fixes a security bug which can allow malicious users to gain root […]

Read more
FreeBSD 13 — timidity++ — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — timidity++ — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 5 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: TiMidity++ — Multiple vulnerabilities Related CVEs: CVE-2017-11546 CVE-2017-11547 CVE-2017-11549 Upstream summary: qflb.wu of DBAPPSecurity reports: Ihe insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 can cause a denial of service(divide-by-zero error […]

Read more
How to Configure Jail Networking on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Configure Jail Networking on FreeBSD 13

Introduction How to Configure Jail Networking on FreeBSD 13 is a core administration task for any FreeBSD 13 server operator. FreeBSD 13 ships with the 15.0-RELEASE kernel, ZFS as the default root filesystem, Capsicum capability sandboxing improvements, and an updated ports tree. Unlike Linux distributions, FreeBSD uses rc(8) for service management, pf for packet filtering, […]

Read more
FreeBSD 13 — mod_dosevasive — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — mod_dosevasive — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: mod_dosevasive — insecure temporary file creation Upstream summary: An LSS Security Advisory reports: When a denial of service attack is detected, mod_dosevasive will, among other things, create a temporary file […]

Read more
FreeBSD 13 — urban — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — urban — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 4 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: urban — stack overflow vulnerabilities Related CVEs: CVE-2005-2864 Upstream summary: Several filename-related stack overflow bugs allow a local attacker to elevate its privileges to the games group, since urban is […]

Read more
FreeBSD 13 — gnutls-devel — multiple vulnerabilities (9 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 13

FreeBSD 13 — gnutls-devel — multiple vulnerabilities (9 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 3 June 2021 Affected versions: FreeBSD 13 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: gnutls — multiple certificate verification issues Related CVEs: CVE-2006-4790 CVE-2009-1415 CVE-2009-1416 CVE-2009-1417 CVE-2009-2730 CVE-2012-1569 CVE-2012-1573 CVE-2014-0092  +1 more Upstream summary: GnuTLS project reports: A vulnerability was discovered that affects the […]

Read more
How to Audit Security with Lynis on FreeBSD 13 — step-by-step FreeBSD 13 tutorial on Progressive Robot

How to Audit Security with Lynis on FreeBSD 13

Introduction FreeBSD 13 is a UNIX-derived operating system renowned for its network stack performance, ZFS integration, and Jail isolation primitives. Setting up audit security with lynis on freebsd 13 on FreeBSD 13 follows the rc.conf/service(8) paradigm rather than systemd, which means enabling a service and configuring its startup options are done differently from any Linux […]

Read more
CHAT